Sunday, March 9, 2025
HomeInternetCritical Vulnerability in Wordpress Ad Inserter Plugin Let Hackers to Execute Arbitrary...

Critical Vulnerability in WordPress Ad Inserter Plugin Let Hackers to Execute Arbitrary PHP Code

Published on

SIEM as a Service

Follow Us on Google News

A critical remote code execution vulnerability in WordPress plugin Ad Inserter, let hackers execute arbitrary PHP code in the vulnerable installations.

The vulnerability was discovered by Wordfence security team and the vulnerability can be executed only by the authenticated users starting from Subscribers to above user levels.

The Ad Inserter used on over 200,000 websites and the functionality of the plugin to insert different kind of ads, opt-in forms and other scripts on the WordPress websites.

This issue is categorized as a critical one and has CVSS Score 9.9, the websites running Ad Inserter 2.4.21 or below are affected.

Wordfence reported the vulnerability to the plugin developer and the patch was released in the next day itself, users are recommended to update with 2.4.22 right away.

With this plugin, an ad preview feature option available which let’s website administrators to see how their ad appears on the web page.

This action can be done only by the website by authenticated users and also the plugin has check_admin_referer(), which ensures the action to be done by site administrator only.

But the vulnerability discovered by Wordfence shows that security control in place: check_admin_referer() is not enough and the nonce has been compromised to get the appropriate privileges.

The Ad Inserter also includes that includes troubleshooting features, which includes a Javascript on every page, according to “Wordfence the Javascript contains a valid nonce for the ai_ajax_backend action and the debugging feature can be triggered by any user who has this special cookie.”

By having the nonce string in hand, an attacker with Subscriber or above user account can exploit the vulnerability in ad preview feature by executing malicious PHP code, explains Wordfence.

By using tools such as WPScan you can scan the WordPress sites for vulnerabilities.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations...

Lumma Stealer Using Fake Google Meet & Windows Update Sites to Launch “Click Fix” Style Attack

Cybersecurity researchers continue to track sophisticated "Click Fix" style distribution campaigns that deliver the...

Fake BianLian Ransom Demands Sent via Physical Letters to U.S. Firms

In a novel and concerning development, multiple U.S. organizations have reported receiving suspicious physical...

Strela Stealer Malware Attack Microsoft Outlook Users for Credential Theft

The cybersecurity landscape has recently been impacted by the emergence of the Strela Stealer...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

Threat Actors Exploit PHP-CGI RCE Vulnerability to Attack Windows Machines

A recent cybersecurity threat has emerged where unknown attackers are exploiting a critical remote...

Critical DrayTek Router Vulnerabilities Expose Devices to RCE Attacks

A recent security analysis of Draytek Vigor routers has uncovered severe vulnerabilities that could...

Multiple Jenkins Vulnerabilities Allow Attackers to Expose Secrets

Jenkins, the widely-used open-source automation server, issued a high-priority security advisory on March 5,...